← Back to the blog 🇲🇽 Mexico · Practical guides · 6 min read

How to look up ALL your SAT certificates (active, expired and revoked) — and why you should check them today

Written for Mexico. This analysis applies to Mexican federal tax law — ISR (income tax), IVA (VAT) and SAT rules — and cites Mexican statutes. Amounts are in Mexican pesos (MXN).

Quick answerThe SAT's Certificate Recovery portal lists, with just your RFC, all your e.firma and digital seal certificates: serial number, type, status and validity dates, with a .cer download. What it's for: anticipating expirations that shut off your invoicing, recovering lost files and — the security reason — spotting issued seals you don't recognize.

Few taxpayers know it exists — and fewer that it's public: the Certificate Recovery tool from the SAT (Mexico's tax administration) lists, by entering just an RFC (federal taxpayer ID), every certificate the authority has issued for that taxpayer: e.firma (the SAT's digital signature) and digital seals (CSD), with serial number, type, status (active, expired or revoked) and exact validity dates — with a direct download of each one's .cer file. Five minutes on that portal answers three questions that are worth money.

Question 1: when does what I use expire?

The e.firma and the CSDs live for 4 years — and they expire silently: no one calls you — one day your invoicing software simply rejects the seal or your return can't be signed (typically on the 17th, of course). The lookup gives you the exact dates of each active certificate so you can schedule renewal with months of breathing room — which is also the easy scenario: an active e.firma renews 100% online; an expired one already requires more steps (and if it's more than a year expired, an in-person appointment). Operating rule: check the portal at the start of every year and schedule renewal 60 days before any piece expires.

Question 2: where did my .cer go?

The classic use: you lost or can't find the .cer file of your e.firma or of a seal (to set up a new invoicing tool, an accounting system, payroll). From the portal you download the .cer of any of your certificates instantly. What the portal can't give you — because the SAT never has it — is your .key file or its password: those exist only where you saved them. If you lost the e.firma's .key, renewal is in order; if you lost a CSD's, you generate a new seal (fast and drama-free). Permanent takeaway: .cer, .key and password are backed up in duplicate, in separate folders per certificate and with names your future self will understand.

Question 3 — the security one: do I recognize all my seals?

The reading almost no one does — and everyone should: the list shows how many CSDs exist under your name and since when. Your tax identity has passed through the hands of accountants, firms, employees and invoicing providers over the years — and an active seal in the wrong hands means someone can issue CFDIs (digital tax invoices) in your name: the raw material of tax-identity theft and of the bogus invoices you later have to disavow. If the lookup shows an active seal you can't place or that stayed with a provider you no longer work with, the answer is immediate: revoke it from CertiSAT with your e.firma and generate a new one under your control. Auditing this list once a year — and at every change of accountant — is basic tax hygiene that takes five minutes. The direct link to the portal is in our Resource Center.

How many active seals exist under your name — and who has them?

If the question made you uncomfortable, that's the point. In the tax-hygiene diagnostic we review exactly this: certificate inventory, who holds what, revocation of what's left over, and the control protocol (who invoices, with which seal, from where) so your tax identity has the same locks as your banking. It's the cheapest audit with the most expensive downside to ignore.

Frequently asked questions

Can anyone see my certificates with my RFC?

The public lookup shows the existence of certificates and their metadata (serial, validity dates, status) and lets you download the .cer — which is, by design, the PUBLIC part of the cryptographic pair. No one can sign or invoice with a .cer: for that you need the .key and its password. The portal's transparency is not the risk; a poorly guarded .key is.

What's the difference between 'expired' and 'revoked'?

Expired = it reached the end of its 4 years and died on its own. Revoked = someone actively canceled it earlier (you, for security, or the authority — the SAT's revocation of seals via articles 17-H/17-H Bis of the CFF, the federal tax code, is its harshest pressure tool, and seeing it on your list without having requested it warrants immediate attention from your advisor).

I renewed my e.firma — do my previous CSDs still work?

CSDs are independent certificates with their own validity — renewing the e.firma does not touch them in the ordinary case (revoking the e.firma, on the other hand, can take them down with it). Check the status of each piece in the portal after any change: that is exactly what it's for.

Aren't the e.firma and the CSD the same thing?

No: the e.firma is your universal legal identity (it signs returns, filings, contracts); the CSD is used exclusively to stamp invoices. You can have several CSDs (one per branch or system) and a single e.firma. Confusing them is the number-one error when setting up invoicing software — our CSD guide untangles it in full.

Let's talk about your case

The first step is always the same: an honest diagnostic of where you stand. Write to us on WhatsApp or call — a reply the same business day.

← Back to the blog